Missivo Privacy Policy

Last updated: 31 August 2026

Missivo is a Shopify app that generates and transmits legally required electronic invoices (EN 16931 formats such as Factur‑X, XRechnung and UBL/Peppol BIS) for business‑to‑business orders placed in a merchant’s store. This policy explains what data the app processes, why, and what happens to it.

Roles

For personal data contained in a store’s orders, the merchant is the data controller and Missivo acts as a data processor: we process order data solely to produce and deliver the invoices the merchant is legally required to issue, on the merchant’s instruction (installing and configuring the app).

Data we process

Missivo does not collect analytics on buyers, does not sell or share data for advertising, and does not process payment card data of any kind.

Why we process it

Solely to (1) generate invoices in the format required by the applicable e‑invoicing mandate, (2) validate business VAT numbers against the European Commission’s VIES service, and (3) where the merchant enables it, transmit invoices through the legally required delivery networks (the Peppol network / French PDP platforms). Legal bases: performance of the app contract with the merchant and the merchant’s own legal obligations (GDPR Art. 6(1)(b) and (c)).

Subprocessors

Retention and deletion

Security

Data is encrypted in transit (TLS) and at rest, hosted exclusively in the EU, with access limited to what the app needs to function. API credentials are stored as platform secrets, never in code.

Your rights & contact

Buyers should direct access/erasure requests to the merchant they purchased from (the controller); we support merchants in fulfilling them via the mechanisms above. Questions about this policy: support@missivo.app.